Apple criticised for persistent Trojan flaw

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS

An Apple patch released last week doesn't completely fix a high-profile Mac OS X flaw, leaving a toehold for cyberattacks, experts said.

The Mac maker released a security update for its operating system on Wednesday to plug 20 holes. The patch arrived after two weeks of intense scrutiny of the safety of OS X, prompted by the discovery of two pieces of malware, and the disclosure of a vulnerability that was deemed "extremely critical" by security monitoring company Secunia.

The update added a function called "download validation" to Apple's Safari, Mail and iChat. The function warns people that a download could be malicious when they click on a link. Before that change, clicking on a link could have resulted in the automatic execution of code on a Mac.

But Apple failed to address a key part of the problem, the fix should be at a lower, operating system level, experts said. It is now still possible for hackers to construct a file that appears to be a safe file type, such as an image or movie, but is actually an application, they said.

"While Apple added a checkpoint to the downloading and execution process, they did not eliminate this vulnerability," said Kevin Long, an analyst at security specialist Cybertrust and a Mac user for 11 years. "If a user can be tricked into opening a file that looks like a picture, the user may actually be opening a malicious script."

After installing the Apple patch, Safari, Mail and iChat in most cases will display a warning when downloading a potentially malicious file. However, the same is not true for other applications that let users receive files, such as Firefox or other Web browsers, third-party email clients, other instant-messaging applications or file-sharing tools. Apple does not offer safeguards for those applications.

Also, Safari won't display an alert for users who have disabled the "Open safe files after downloading" option in the Web browsers. Security experts urged users to disable this setting after initial details of the flaw were disclosed since it made users more vulnerable.

ZDNet UK sister site CNET News.com was alerted to the limitations of the patch by readers, who described themselves as "concerned Apple fans". Security experts confirmed the existence of an issue.

Apple acknowledged that, despite its patch, it is still possible to make a malicious file look innocent.

"It is definitely possible on the Mac and on any platform to create an application and try to pretend that it is something that its not. That's the definition of Trojans," Philip Schiller, Apple's senior vice-president of worldwide product marketing, said in an interview. "There are Trojans in the world, I have yet to see a successful one on the Mac, but there are such things in the world as Trojans."

However, with its security updates for Safari, Mail and iChat, Apple believes it cut off access for such Trojans. "The tools most people use [now] have built-in validation for things before they even get to the desktop," Schiller said. "The point of where people get the file is often through the browser and mail and instant messaging."

Apple's security fix is an important first step, said Michael Lehn, doctoral candidate and research assistant at the University of Ulm in Germany.

"I think Apple did the right thing," said Lehn, who first disclosed the Mac OS X vulnerability. "The fact that a script gets executed automatically had to be fixed immediately. They just have to go further."

Microsoft Windows users have grown accustomed to a seemingly incessant stream of computer worms, viruses and security vulnerabilities. The same is not true for Mac owners. Going by fan forum postings, many Apple customers believe their systems are impervious to cyberattacks.

Lehn said it was good that Apple made the fix it did, even though it wasn't complete. "In my opinion, it is better to release several security updates," he said. "Apple fixed the serious part very quickly and that's good."

The unresolved vulnerability is due to a problem with the Mac OS Finder, the component of the operating system used to view and organise files, Lehn said. The operating system assigns an identifying icon for a file based on the file extension. However, it decides which application will handle the file based on metadata.

A malicious file can be masked to initially look innocent — for example, like a JPEG image — yet execute when opened.

"While the Finder allows the user to find out that the file is an executable — with a right-click, for example — many users will not do that. They just look at the icon, which can be the same typically used for innocent files," Lehn said.

This means that if an attacker were able to trick a user into downloading a malicious file, that file can still be masked as an innocent file. By pulling this Trojan-style trick, a user might believe he is getting a movie or an image, but running it could wipe all user data on the hard drive, for example.

Cybertrust's Long sounded a note of restraint about the risk posed by the remaining problem. "It's true that this security update does not translate into Macs that are invulnerable," Long said. "However, Apple has put some things in place to assist users in detecting questionable files... there's no need to freak out about this."

Apple knows about the issue with the icons, Lehn said. He and other security researchers have alerted the company, he noted.

Apple is thankful for the feedback, Schiller said. The company recognises that adding more validation, perhaps at a deeper level in the operating system, could help protect users of applications other than Safari, Mail and iChat.

"If the method we use works for most people most of the time and some people use some other tools and would like to have some more support for validation, we think that's good feedback we'll consider for the future," he said. "We always try to make this better and stronger."

This vulnerability has actually existed for years in Mac OS, Long said. If attackers really were targeting Mac users, numerous examples of malicious code taking advantage of the flaw would be in circulation. "In fact, that is not the case," he said. "While it can be a factor in a system being compromised, this vulnerability by itself does not justify panic."

ZDNet UK sister site CNET News.com reader Eric also pointed out that the problem has nagged Apple for years, yet it has not been fixed. "This vulnerability derives from the exact same flaw deep inside the OS that should have been addressed by Apple several times in the past two years," wrote Eric, who asked for his last name not to be used.

The issue is similar, Eric wrote, to problems Apple had with the security of its Widgets, or small programs that were introduced in Tiger for the Dashboard. Before a security patch in May last year, widgets would download and install without warning.

One factor that makes addressing the remaining flaw important is that people aren't always as wary as they should be online. Computer users tend to click through warnings, eager to get the promised content.

"The only thing that the update does is update Safari and Mail to provide the user a warning before downloading the file," Eric wrote. "But this message is so vague and redundant for all downloads... It's second nature for any and all users to simply click 'continue'."

Such security issues are, of course, not exclusive to the Mac. If a user can be tricked into downloading and opening a file, that user's system can be compromised. "This is true regardless of the operating system being used. It is a universal vulnerability," Long said.

Talkback

Hmm, I suspect the 'Concerned Apple Fans' are actually 'Paid Microsoft Employees' trying to make OSX look bad....

via Facebook 7 March, 2006 14:19
Reply

For a more balanced opinion go here http://test.doit.wisc.edu/

via Facebook 8 March, 2006 10:33
Reply

Apple did their part. Now it's up to the users.

There is the ability to have custom icons on files. I don't want this ability taken away.

There is the ability to have a different file type and not rely on a three letter extension that may or may not be there. This is one of the reasons why MacOS X is nicer to work with. I can have .txt files that open in word, and other ones that open in BBEdit. I don't want this ability taken away either.

The rest is up to the user. Stop clicking on unknown attachments - even from known senders.

via Facebook 8 March, 2006 15:52
Reply

So Apple should be like Microsoft and wait? Wait for a third party to issue a patch becuase theirs might be better? Not releasing a patch the at least lessens the threat while working on a better fix?

Apple did the responsible first step. I would hope that Apple is still working on a better fix, bit at least they responded.

via Facebook 9 March, 2006 16:27
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Freebies202

Duplicate comments are not made intentionally. Its very good to know that now you are keeping check on this problem because sometimes a commenter...

7 hours ago by Freebies202 on Microsoft fixes blog comments, speeds up blogs with open source
kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

15 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

17 hours ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

17 hours ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

19 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

21 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

22 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

23 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

23 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

24 hours ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

1 day ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

1 day ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

1 day ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

1 day ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

1 day ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

2 days ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

2 days ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

2 days ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

2 days ago by Moley on A tale of two distros: Ubuntu and Linux Mint